Head of IT Sec AS Attack Surface Mgmt

Sista ansökningsdag: 25 juli
Arbetsort: Bangalore, Gurgaon, Noida, Stockholm
Publicerat: För 5 timmar sedan
Kategorier: Chef & Ledning Data & IT Säkerhet & Skydd Teknik & Ingenjör
About our opportunity
We are part of the global CIO function tasked to deliver world-class built-in security in Ericsson. Our 100+ employees’ organization is global with the main hubs located in Sweden (HQ), India, USA, and the Philippines. We are inviting the application for Head of IT Sec AS Attack Surface Management.
In this role, you will have the chance to be part of a passionate global team dedicated to fulfilling Ericsson’s emerging journey building a strong, resilient, purposed and sustainable IT Security capability. Mandated to protect our company assets from emerging threats and risks, you will together with your colleagues lead the way to develop the future IT Security concepts and technology roadmaps in Ericsson
You will
- Define and execute the enterprise-wide strategy for attack surface management aligned with the broader cybersecurity roadmap.
- Build and lead a high-performing ASM team covering asset discovery, vulnerability management, cloud security, penetration testing, and red teaming.
- Partner with business, IT, DevOps, and architecture teams to embed ASM principles in solution design and lifecycle.
- Oversee continuous asset discovery and inventory (including shadow IT, rogue systems, and exposed services).
- Manage vulnerability identification, classification, prioritization, and remediation across infrastructure, applications, and cloud environments.
- Lead API and third-party attack surface monitoring and ensure proactive risk reduction.
- Drive adoption of ASM platforms, exposure management tools, and threat intelligence integrations.
- Define KPIs, KRIs, and reporting for ASM effectiveness and risk posture across business units.
- Ensure alignment with security frameworks (e.g., NIST CSF, ISO 27001, MITRE ATT&CK) and regulatory compliance.
- Lead red/purple team exercises to validate security posture and feed improvements into the ASM program.
- Drive coordination with vulnerability management, SOC, architecture, DevSecOps, and compliance teams.
- Continuously evaluate ASM capabilities through tabletop exercises and exposure simulations.
The Skills You Bring:
- Bachelor’s or master’s degree in computer science, Information Security, or related field.
- 10+ years in cybersecurity with at least 4 years in a leadership role managing attack surface or vulnerability management programs.
- Relevant certifications such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), or equivalent.
- Proven experience in managing hybrid IT environments including cloud (AWS, Azure, GCP), SaaS, and on-premises assets.
- Expertise in tools such as ASM platforms (e.g., CyCognito, Randori, Microsoft Defender ASM), VM platforms (Tenable, Crowdstrike, Qualys, Rapid7), and API security tools.
- Deep understanding of cloud security controls, CI/CD pipelines, external threat modeling, and exposure management.
- Familiarity with MITRE ATT&CK, NIST 800-53/CSF, OWASP Top 10, CIS Benchmarks.
- Strong leadership, stakeholder management, and team development skills.
- Ability to communicate technical risks and attack surface exposures in business language to executives and board members.
- Excellent leadership and people management skills, with the ability to inspire and guide a team of security professionals.
Why join Ericsson?
At Ericsson, you´ll have an outstanding opportunity. The chance to use your skills and imagination to push the boundaries of what´s possible. To build solutions never seen before to some of the world’s toughest problems. You´ll be challenged, but you won’t be alone. You´ll be joining a team of diverse innovators, all driven to go beyond the status quo to craft what comes next.
What happens once you apply?
Click Here to find all you need to know about what our typical hiring process looks like.
Encouraging a diverse and inclusive organization is core to our values at Ericsson, that's why we champion it in everything we do. We truly believe that by collaborating with people with different experiences we drive innovation, which is essential for our future growth. We encourage people from all backgrounds to apply and realize their full potential as part of our Ericsson team. Ericsson is proud to be an Equal Opportunity Employer. learn more.
Primary country and city: India (IN) || Gurgaon
Req ID: 768823
Senaste jobben från Ericsson
-
Strategic Product Manager
För 5 timmar sedan
-
Head of IT Sec AS Attack Surface Mgmt
För 5 timmar sedan
-
ICT Operation Manager (Entry Level)
För 6 timmar sedan
-
Radio developer
För 6 timmar sedan
-
RMIC Validation Engineer
För 6 timmar sedan
-
Development Environment Developer
Igår
-
CPI Lead
Igår
-
Radio SW 5G Developer
Igår
-
Senior Product Support Engineer
23 juni
-
Research Manager
23 juni
-
Product Support Engineer
23 juni
-
Data Governance Lead - GO Beyond Program
23 juni
-
Enterprise IT Security Architect
23 juni
-
Senior Linux Engineer
23 juni
-
Junior FPGA Developer
23 juni
-
Thermal Designer
23 juni
-
Patent Professional
23 juni
-
Developer ASIC Backend
23 juni
-
Senior Software Engineer
19 juni
-
Radio Solution Driver
18 juni
-
Senior Security Assurance Project Manager
18 juni
-
Product Information Architect
18 juni
-
Radio ASIC Algorithm Developer
18 juni
-
Senior Developer Filter Design
17 juni
-
Test Manager
17 juni
-
Radio Test Integration RF
17 juni
-
System Architect ASIC
17 juni
-
ASIC Architect
17 juni
-
Developer
17 juni
-
Software Developer Radio Synchronization
16 juni
-
Industrial PhD student WASP
16 juni
-
E2E Software Onboarding Flow Owner
16 juni
-
Principal Software Engineer
16 juni
-
RAN Digital Twin Researcher
16 juni
-
IT Product Owner - Sourcing IT - Go Beyond Program
16 juni
-
Researcher: Services and APIs
16 juni
-
Senior ASIC Design Lead in Lund/Stockholm:
16 juni
-
Verification Engineer E2E
16 juni
-
Strategy Analyst
16 juni
-
Strategy Manager
16 juni
-
Strategy Director
16 juni
-
IT Product Owner
13 juni
-
Service Owner
12 juni
-
Software Developer
12 juni
-
Senior AI Security Technology Specialist
12 juni
-
Test Engineer
11 juni
-
System Architect ASIC
9 juni
-
ASIC SoC Verification Engineer
4 juni
-
Senior ASIC IP Verification
3 juni
-
Hardware Systems Expert
3 juni